AI Voice Phishing Bypasses MFA, Steals Accounts with Fake Banking Pages
Key Takeaways A sophisticated phishing-as-a-service (PhaaS) operation, “Balonx Sistema,” is actively targeting Mexican financial institutions. The campaign employs AI-generated voice...
Key Takeaways
- A sophisticated phishing-as-a-service (PhaaS) operation, “Balonx Sistema,” is actively targeting Mexican financial institutions.
- The campaign employs AI-generated voice calls and real-time fake banking pages to bypass multi-factor authentication (MFA).
- It has already compromised over 1,100 individuals, stealing credentials and financial data.
- Balonx Sistema leverages a multi-stage attack that can escalate from account phishing to full device takeover via an Android remote access trojan (RAT).
AI Voice Phishing Bypasses MFA, Steals Accounts with Fake Banking Pages
Cybercriminals are deploying an advanced phishing-as-a-service (PhaaS) platform that combines AI-powered voice calls with meticulously crafted fake banking websites to compromise user accounts, even circumventing multi-factor authentication (MFA) protocols. This sophisticated operation, identified as Balonx Sistema, provides attackers with a dynamic, real-time view of a victim’s interaction with the phishing site, enabling them to solicit sensitive information precisely when required.
Table Of Content
The Balonx Sistema campaign has set its sights on over 20 financial institutions in Mexico, successfully exfiltrating credentials and other financial data from more than 1,100 victims since at least October 2023. The platform operates as a subscription service, significantly lowering the entry barrier for threat actors seeking to launch large-scale banking scams. It offers various subscription tiers, including individual and “office” plans, which grant multiple operators controlled access to active victim sessions and a selection of targeted banking brands.
Security researchers at Group-IB uncovered the platform after analyzing leaked GitHub repositories that exposed critical components of its infrastructure and affiliate network. According to Group-IB said in a report, Balonx Sistema integrates live phishing, an Android remote access tool, and automated voice fraud. This combination creates a blended attack that transitions seamlessly from an urgent phone call to a convincing fraudulent website, and in some instances, culminates in the installation of a malicious mobile application. This complex methodology highlights the inadequacy of SMS-based MFA alone against determined attackers who actively guide victims through the compromise process.
Sophisticated Phishing with Real-time Interaction
Balonx Sistema utilizes a persistent WebSocket connection to maintain a real-time link between the phishing page displayed to the victim and the criminal’s command-and-control panel. This allows for dynamic interaction. Once a target inputs their banking credentials, the operator can immediately relay these details to the legitimate bank’s website, triggering an MFA prompt. Simultaneously, a corresponding fake verification screen is presented to the victim on the phishing site.
The precise timing of these prompts is crucial to the scam’s effectiveness. Victims may be asked for various verification details, including SMS codes, purchase approval codes, ATM PINs, full card details, or cardless withdrawal codes, all under the guise of a routine bank security check. Balonx Sistema is equipped with 14 distinct screen types, enabling affiliates to adapt the narrative as the session progresses and compel the victim to complete all requested steps. This technique mirrors advanced phishing attacks that bypass MFA by positioning the attacker as an intermediary between the user and the legitimate service, rather than merely collecting static credentials. This “man-in-the-middle” approach makes the fraudulent page appear authentic because it responds dynamically while the genuine bank session is active.
A dedicated “CallFlow” module further enhances the social engineering aspect of the attack. This module incorporates a language model, speech-to-text processing, and synthetic speech to conduct automated calls, impersonating a fabricated bank representative named “Carolina.” This automation allows the platform to execute outbound campaigns without requiring a human operator for every conversation, making suspicious calls feel personalized and responsive. This danger is also evident in recent reports of automated bank support calls, where callers can direct targets to fake pages, then exploit these interactions to obtain credentials or persuade them to install malicious software.
Mobile Access Extends the Fraud
Beyond credential theft, Balonx Sistema also propagates a Spyroid-based Android remote access trojan (RAT). This malware is distributed via a deceptive screen that masquerades as a bank-protection alert. Upon successful installation, the malicious app establishes a persistent connection with its command-and-control server, enabling criminals to exfiltrate screen content, keystrokes, SMS messages, and activity from legitimate banking applications. The RAT’s persistent connection is designed to prevent timeouts, granting the operator uninterrupted access to the compromised device long after the initial deception.
This second stage elevates an account-phishing attempt into a potential device takeover. This aligns with a broader trend in Android remote-control banking threats, where attackers use fraudulent websites or calls to trick users into installing malicious applications outside official app stores, thereby gaining deeper access to the victim’s smartphone.
What You Should Do
- Verify Calls Independently: If you receive an unexpected call from your bank, terminate the call and independently contact your bank using the official phone number listed on your bank card or within the official banking app. Do not use any numbers provided by the caller.
- Never Install Unsolicited Apps: Refrain from installing any applications suggested by an unverified caller or website. Always download banking apps directly from official app stores (Google Play Store, Apple App Store).
- Guard Sensitive Information: Be highly suspicious of any requests for your ATM PIN, CVV, or to scan your bank card over the phone or on an unfamiliar website. Legitimate banks will rarely ask for this information in such a manner.
- Monitor for Suspicious Activity: Financial institutions should actively monitor their infrastructure for indicators of compromise (IoCs) related to Balonx Sistema, including unusual WebSocket activity and suspicious redirect chains.
- Enhance MFA for High-Value Users: For critical accounts and high-value users, implement hardware security keys based on FIDO2 standards. These are significantly more resilient to real-time relay attacks than SMS-based one-time passwords.
- Report and Act Immediately: If you suspect you have shared information with a fraudulent entity, immediately contact your bank through verified official channels, reset all relevant credentials, and thoroughly review your recent transaction history for any unauthorized activity.
Indicators of Compromise (IoCs):-
| Type | Indicator | Description |
|---|---|---|
| Domain | Aclaraciones-digital[.]online | Balonx campaign infrastructure |
| Domain | soporte-aclaracion[.]xyz | Balonx campaign infrastructure |
| Domain | balonx[.]online | Balonx campaign infrastructure |
| Domain | callbalonx[.]info | CallFlow AI vishing login portal |
| Domain | panelbalonxfs[.]xyz | CallFlow FreePBX backend and UCP |
| IP Address | 196.251.84[.]11 | Android RAT command-and-control server |
| Network Port | 7771/TCP | Android RAT command-and-control port |
| IP Address | 85.31.235[.]109 | CallFlow SIP server |
| Network Port | 5160/TCP | CallFlow SIP service port |
| API Endpoint | panelbalonxfs[.]xyz/admin/api/api/gql | GraphQL API |
| API Endpoint | panelbalonxfs[.]xyz/admin/api/api/rest | REST API |
| API Endpoint | panelbalonxfs[.]xyz/admin/api/api/token | Authentication token endpoint |
| WebSocket Path | /ws | WebSocket command-and-control path on active Balonx phishing domains |
| Android Package | sacred.explosion | Malicious Android RAT package name |
| Android Main Class | bxelllolzxqfmaszk1049 | Main class associated with the malicious APK |
| Base64 C2 Host Field | MTk2LjI1MS44NC4xMQ== | Encoded Android RAT command-and-control host field |
| Base64 C2 Port Field | Nzc3MQ== | Encoded Android RAT command-and-control port field |
| Delivery Screen | PROTECCION_BANCARIA | Fake bank-protection screen used to distribute the malicious APK |
Note: IP addresses and domains are intentionally defanged (e.g., [.]) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM.
Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.



No Comment! Be the first one.